Skip to content

1301.0.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 14:51
fd2ab1c

@metamask/subscription-controller 11.0.0

Added

  • Add SubscriptionDelegationService:startSubscriptionWithDelegation to orchestrate one immutable approval for MM Pay funding, recurring-payment delegation signing, CHOMP registration, and subscription creation (#10339)
    • Before the approval, call MoneyAccountUpgradeController:forceUpgradeAccount with the payer address so the Money Account vault delegations and CHOMP intents exist; the Subscription API validates them server-side.
    • Add exported approval, funding, and prepared-bundle contracts.
    • Bind recurring permissions to the token, amount, period, start, and zero native value, and verify reusable delegation hashes with CHOMP.
    • Derive trial timing from authoritative subscription state.
    • Add optional skipApproval to StartSubscriptionWithDelegationRequest to bypass the ApprovalController:addRequest consent and funding step; the caller is then responsible for consent and funding.
  • Add SUBSCRIPTION_STATUSES.awaitingFunds (awaiting_funds) for crypto subscriptions that are waiting for the payer to fund the first invoice (#10566)
    • SubscriptionController:submitSubscriptionCryptoApproval treats it like past_due / unpaid: a new approval updates the existing subscription's payment method.

Changed

  • BREAKING: StartCryptoSubscriptionResponse (returned by SubscriptionService:startSubscriptionWithCrypto, SubscriptionController:startSubscriptionWithCrypto, and SubscriptionDelegationService:startSubscriptionWithDelegation) is now the created Subscription instead of { subscriptionId, status }, matching what POST /subscriptions/crypto actually returns (#10566)
    • Read response.id instead of response.subscriptionId. response.status is unchanged.
    • Previously the response failed validation on every successful call, so the crypto start flow always threw.
  • BREAKING: Widen SubscriptionDelegationServiceMessenger so SubscriptionDelegationService:startSubscriptionWithDelegation can call the actions it needs (#10339)
    • The messenger must now allow ApprovalController:addRequest, MoneyAccountUpgradeController:forceUpgradeAccount, SubscriptionController:getState, SubscriptionController:getSubscriptions, and SubscriptionController:startSubscriptionWithCrypto.
    • Clients that construct this messenger must delegate those actions before calling startSubscriptionWithDelegation. A messenger typed against the previous SubscriptionDelegationServiceMessenger is no longer assignable.
  • Restrict cash-subscription delegations created by SubscriptionDelegationService:prepareDelegation so the ERC-20 transfer recipient must be the pricing chain paymentAddress (subscription treasury), via an AllowedCalldataEnforcer caveat. (#10427)
    • The caveat pins calldata from offset 0 to the transfer(address,uint256) selector followed by the ABI-encoded treasury address, matching the terms CHOMP expects.
    • prepareDelegation throws when the pricing paymentAddress is not a valid address.
    • Stored delegations without a matching recipient caveat are no longer reused; a new delegation is created and signed instead.
  • Stop adding the ValueLteEnforcer caveat to cash-subscription delegations created by SubscriptionDelegationService:prepareDelegation, because CHOMP only accepts ERC20PeriodTransferEnforcer and AllowedCalldataEnforcer for this intent type. (#10427)
    • Stored delegations that still include a ValueLteEnforcer caveat are no longer reused; a new delegation is created and signed instead.
  • Add @ethersproject/abi ^5.7.0 as a dependency (#10427)
  • Add @metamask/money-account-upgrade-controller ^5.1.0 as a dependency (#10339)
  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.0.1 (#10462)
  • Bump @metamask/base-data-service from ^2.0.0 to ^2.1.0 (#10502)
  • Bump @metamask/money-account-balance-service from ^3.0.0 to ^3.1.1 (#10502, #10544)
  • Bump @metamask/chomp-api-service from ^5.0.0 to ^6.0.0 (#10505)
  • Bump @metamask/money-account-utils from ^2.0.1 to ^2.1.0 (#10505)
  • Bump @tanstack/query-core from ^5.89.0 to ^5.103.2 (#10511)

Fixed

  • Stop rejecting Subscription API responses whose lastInvoice omits updatedAt or whose card payment method omits displayBrand; both fields are optional in the API and are now optional on SubscriptionInvoice and SubscriptionCardPaymentMethod (#10566)
    • Previously a subscription with a lastInvoice failed validation and getSubscriptions threw.

@metamask/wallet 15.1.0

Changed

  • Grant SubscriptionDelegationService access to the additional messenger actions required by SubscriptionDelegationService:startSubscriptionWithDelegation (#10339)
    • ApprovalController:addRequest, MoneyAccountUpgradeController:forceUpgradeAccount, SubscriptionController:getState, SubscriptionController:getSubscriptions, and SubscriptionController:startSubscriptionWithCrypto
    • Hosts that supply their own root messenger must allow these actions and register MoneyAccountUpgradeController before calling SubscriptionDelegationService:startSubscriptionWithDelegation.
  • Bump @metamask/claims-controller from ^1.0.1 to ^1.0.2 (#10459)
  • Bump @metamask/shield-controller from ^7.0.2 to ^7.0.3 (#10459)
  • Bump @metamask/subscription-controller from ^10.0.0 to ^11.0.0 (#10459, #10570)
  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.0.1 (#10462)